2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34691MEDIUM6.5Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticate...
CVE-2024-34690MEDIUM5.4SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t...
CVE-2024-34688HIGH7.5Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS att...
CVE-2024-34686MEDIUM6.1Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which ...
CVE-2024-34684MEDIUM6On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administr...
CVE-2024-34683MEDIUM6.5An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file,...
CVE-2024-33001MEDIUM6.5SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding th...
CVE-2024-2473MEDIUM5.3The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9...
CVE-2024-28164MEDIUM5.3SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about...
CVE-2024-0653MEDIUM4.8The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2024-0627MEDIUM5.4The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fiel...
CVE-2024-37178MEDIUM5SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)...
CVE-2024-37177HIGH8.1SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are expo...
CVE-2024-37130HIGH7.8Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability v...
CVE-2024-22261MEDIUM5.5SQL-Injection in Harbor allows priviledge users to leak the task IDs
CVE-2024-22244MEDIUM6.1Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
CVE-2024-37289HIGH7.8An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ...
CVE-2024-37169MEDIUM5.3@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if...
CVE-2024-37168MEDIUM5.3@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.1...
CVE-2024-37166HIGH8.9ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-control...
CVE-2024-36473MEDIUM5.3Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack ...
CVE-2024-36471HIGH7.5Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project adm...
CVE-2024-36419MEDIUM6.1SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prio...
CVE-2024-36359MEDIUM5.4A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could all...
CVE-2024-36358HIGH7.8A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now